AFAICT from TFA the arrangement with Collabra was illegal. I think the frustration was that there is no vote to be had on how to proceed in a way that
continues to be illegal. You can vote for a reform you can propose another actionable reform, or you can be thrown out.. And here we are?
I pay a lot of attention when someone claims to have solved a problem I suspect to be NP-hard. There are a lot of possible explanations, for example they may have an incorrect measurement function or they may have chosen a simpler related problem that isn't really NP-hard, or both.
I spend some time going through what programmers wrote over the past years and many of them were rewarded for getting things done quickly with no complaints.. The more diligent ones probably didn't last since they got things done correctly which takes a lot more time and thought.
I think such situations are rather big risk that a community that already wasn't very active atrophies or splits and then atrophies. With code bases like that there's also a lot of maintenance so being able to run an old version is not necessarily enough.
One could say the same thing about virus scanners. They are obviously too little too late "security" so standards that require them have given up on real requirements like a way to achieve actual assurance of no buffer overflows. Nonetheless, an implementation to such a standard that chooses any off the shelf scanner is a lot less work than implementing a new scanner.
This is exactly the situation I think of when I hear news of rescue missions. Running a rescue in a place with functional air defense is a recursive rescue problem that could quickly get out of control.
In my view it is more important to stop using software keys so probably use sk (fido) for both host and user.. From there CAs would be a next step.. The level of documentation and example setups is astoundingly poor if you even look at step 2 for any feature. I.e. SK keys are reasonably understood for user keys but the setup as host keys is vague and needs testing to see if it really works.
Eh, with browsers you can tell the user to go to hell if they don't like a secure but broken experience. The problem in most software is that you commit to bad ideas and then have to upset people who have higher status than the software dev that would tell them to go to hell.
I think most far from center paper writers are more successful if they don't let reality limit their ideas. Probably few consider a real idiot with enough power to ruin them as a threat when they start putting pen to page.